Group Purchasing
Group Purchasing
UPDATED

LDR512: Security Leadership Essentials for Managers

LDR512Cybersecurity Leadership
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Frank Kim
Frank Kim
LDR512: Security Leadership Essentials for Managers
Course authored by:
Frank Kim
Frank Kim
  • GIAC Security Leadership (GSLC)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 25 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Gain essential technical and leadership skills to effectively manage security programs, covering key topics like security architecture, vulnerability management, cloud security, and GenAI security.

Course Overview

LDR512 is security manager training that equips security leaders with the technical and leadership skills needed to manage security programs, covering essential topics like frameworks, vulnerability management, cloud security, and generative AI (GenAI). As a foundational cyber security management course, it also prepares professionals for the GSLC certification (GIAC Security Leadership Certification). Through hands-on Cyber42 simulations, participants build real-world skills for developing effective security teams and managing information risk.

Leading Security Initiatives to Manage Information Risk

Take this security management course to learn the key elements of any modern security program. LDR512 covers a wide range of security topics across the entire security stack. Learn to quickly grasp critical information security issues and terminology, with a focus on security frameworks, security architecture, security engineering, computer/network security, vulnerability management, cryptography, data protection, security awareness, cloud security, application security, DevSecOps, GenAI security, and security operations.

The training course uses the Cyber42 leadership simulation game to put you in real-world scenarios that spur discussion and critical thinking of situations that you will encounter at work. Throughout the class you will participate in 25 Cyber42 activities.

Hands-On Security Manager Training

This leadership focused security training course uses case scenarios, group discussions, team-based exercises, in-class games, and a security leadership simulation to help students absorb both technical and management topics. About 60-80 minutes per day is dedicated to these learning experiences using the Cyber42 leadership simulation game. 

This leadership simulation game is a continuous tabletop exercise where students play to improve security culture, manage budget and schedule, and improve security capabilities at a fictional organization. This puts you in real-world scenarios that spur discussion and critical thinking of situations that you will encounter at work.  These activities develop real-world decision-making skills central to cyber security management and are excellent preparation for leadership certifications like the GSLC certification.

  • Section 1
    • Cyber42 Watt's Warehouse Company Overview
      • Calibration Lab
      • Round 1 Initiative Selection
      • Challenge 1: Whither Watt's Warehouse
      • Challenge 2: Institutionalizing Security
      • Challenge 3: Board Briefing 
  • Section 2
    • Cyber42 Round 1
      • Challenge 4: Network Security Implementation
      • Challenge 5: End User Security
      • Challenge 6: To Serve and Protect
      • Challenge 7: AI Data Deal
  • Section 3
    • Cyber42 Round 2
      • Initiative Selection
      • Challenge 8: Industry Breach
      • Challenge 9: Security Misconfiguration
      • Challenge 10: Miracle on DevOps Way 
      • Challenge 11: Shadow AI
  • Section 4
    • Cyber42 Round 3
      • Initiative Selection
      • Challenge 12: Patching Problems
      • Challenge 13: Let It Be Known!
      • Challenge 14: Tough Negotiations
      • Challenge 15: Managing Resistance 
  • Section 5
    • Cyber42 Round 4
      • Initiative Selection
      • Challenge 16: The High Price of Visibility
      • Challenge 17: Cost Cutting
      • Challenge 18: Ransomware Response
      • Challenge 19: New Guy in Town
      • Challenge 20: Opportunity Knocks 

Syllabus Summary 

  • Section 1 - Governance to plan your security program 
  • Section 2 - Architecture to design your security capabilities 
  • Section 3 - Engineering to build your security capabilities 
  • Section 4 - Build and lead the team, process, and culture 
  • Section 5 - Run operations to manage and mitigate attacks 

Author Statement

"This course covers all the topics I should have known before I started my first security management job. I was thrust into a leadership position and realized I had to convey security concepts in ways that non-technical people could understand. At the same time, I needed a broad view of everything in the security program and the different domains of cybersecurity. In short, I had to learn about the work of managing security. That is why this course focuses on the big picture of securing the enterprise, from governance and architecture all the way to the technical security topics that serve as the foundation for any security manager. Ultimately, the goal of the course is to ensure that you, the advancing manager, can make informed choices to improve security at your organization."

- Frank Kim

What You’ll Learn

  • Apply cybersecurity frameworks and assess risks
  • Lead technical teams and manage security projects
  • Develop vulnerability management and SOC programs
  • Integrate security in DevOps and automate with IaC
  • Foster a security-aware culture and shared knowledge
  • Secure modern architectures, including cloud and GenAI
  • Communicate effectively with technical teams

Business Takeaways

  • Develop leaders that know how to build a modern security program
  • Anticipate what security capabilities need to be built to enable the business and mitigate threats
  • Create higher performing security teams

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR512: Security Leadership Essentials for Managers.

Section 1Building Your Security Program

This section introduces essential knowledge for security leaders, covering cybersecurity frameworks, risk management, policy development, and team structure to support effective security program management.

Topics covered

  • Security Frameworks
  • Understanding Risk
  • Security Policy
  • Program Structure

Labs

  • Calibration Lab
  • Cyber42 Round 1 Initiative Selection
  • Whither Watt's Warehouse
  • Institutionalizing Security
  • Board Briefing

Overview

The course starts with a tour of the information that effective security managers and leaders must know to function in the modern security environment. This includes an understanding of the different types of cybersecurity frameworks available to structure your security team and program. Risk is central to effective information security management, so we'll discuss key risk concepts in order to lay the foundation for effective risk assessment and management. Security policy is a key tool that security managers use to manage risk. We'll cover approaches to policy to help you plan and manage your policy process. Finally, we'll discuss security functions, reporting relationships, and roles and responsibilities to give the advancing manager a view into effective security team and program structure.

Full Lab Details

  • Cyber42 Watt's Warehouse Company Overview
  • Calibration Lab
  • Cyber42 Round 1 Initiative Selection
  • Cyber42 Round 1 Challenge #1: Whither Watt's Warehouse
  • Cyber42 Round 1 Challenge #2: Institutionalizing Security
  • Cyber42 Round 1 Challenge #3: Board Briefing

Full Topic Details

  • Security Frameworks
    • Control, Program, and Risk Frameworks
  • Understanding Risk
    • Risk Concepts
    • Calibration
    • Risk Assessment and Management
  • Security Policy
    • Purpose of Policy
    • Risk Appetite Statement
    • Policy Planning
    • Managing Policy
  • Program Structure
    • Reporting Relationships
    • Three Lines of Defense
    • Roles and Responsibilities
    • Security Functions

Section 2Technical Security Architecture

This section covers traditional and modern security architectures, focusing on network security, endpoint controls, cloud security with AWS, IAM risks, and the Zero Trust Model to address evolving security challenges.

Topics covered

  • Security Architecture Overview
  • Network Security
  • Host Security
  • Cloud Security
  • Identity and Access Management (IAM)

Labs

  • Network Security Implementation
  • End User Security
  • To Serve and Protect
  • AI Data Deal

Overview

Section Two provides coverage of traditional and modern security architectures focused on technical topics. This includes a thorough discussion of network security that is modeled around the various layers of the network stack. As modern attacks are also focused on the computing devices, we cover malware and attack examples along with corresponding host security controls for the endpoint and server. The cloud is a major initiative that is changing the way organizations operate and design their controls. To get ready for these initiatives, we provide an overview of Amazon Web Services (AWS) to serve as a reference point and discuss key cloud security issues. As the rapid rise of cloud adoption has led to identity becoming the new perimeter, we also provide an overview of key Identity and Access Management (IAM) risks and capabilities. The cloud, the rise of mobile devices, and other factors are highlighting weaknesses in traditional, perimeter-oriented security architecture which leads into a discussion of the Zero Trust Model.

Full Lab Details

  • Cyber42 Round 1 Challenge #4: Network Security Implementation
  • Cyber42 Round 1 Challenge #5: End User Security
  • Cyber42 Round 1 Challenge #6: To Serve and Protect
  • Cyber42 Round 2 Challenge #7: AI Data Deal

Full Topic Details

  • Security Architecture Overview
    • Models and Trends
    • Security Architecture Frameworks
    • Cyber Defense Matrix
  • Network Security
    • Layer 1 and 2
      • Overview and Attacks
    • Layer 3
      • VPNs and IPSec
    • Layer 4
      • TCP and UDP
    • Application Layer
      • Proxies, NGFW, IDS/IPS, NSM 
  • Host Security 
    • Malware and Attack Examples 
    • Host Security Controls 
      • EPP, EDR, HIDS/HIPS, FIM, Allowlisting, Sandboxing 
  • Cloud Security
    • Cloud Security Fundamentals
    • AWS Security Reference Architecture
    • AWS Overview
    • Cloud Security Attack Example and Controls
    • Cloud Security Tools
      • CSPM, CWPP, CASB
    • Cloud Security Models
      • Cloud Security Alliance (CSA) Guidance, Well-Architected Frameworks, Cloud Adoption Frameworks
  • Identity and Access Management (IAM)
    • Authentication Factors
    • Authentication and Access Attacks
    • Passwordless, passkeys, and FIDO2
    • IAM Security Capabilities
  • Zero Trust
    • Principles and Best Practices
    • Zero Trust Network Access (ZTNA)
    • Variable Trust

Section 3Security Engineering

Section three covers security engineering best practices, including cryptography, application security with DevSecOps, Infrastructure as Code (IaC), and securing GenAI and Large Language Models (LLMs).

Topics covered

  • Security Engineering
  • Data Protection
  • Application Security
  • DevSecOps

Labs

  • Cyber42 Round 2 Initiative Selection
  • Industry Breach
  • Security Misconfiguration
  • Miracle on DevOps Way
  • Shadow AI

Overview 

Section Three focuses on security engineering best practices. This includes building an understanding of cryptography concepts, encryption algorithms, and applications of cryptography which are foundational elements of building any secure system. Managers must also be knowledgeable about software development processes, issues, and application vulnerabilities. We cover application security and leading development processes built on DevSecOps. Current engineering approaches also include modern Infrastructure as Code (IaC) approaches and tools to automate consistent deployment of standard configurations. Finally, GenAI and agentic AI have led to the growth of AI usage and newer LLM application architectures which need to be secured. 

Full Lab Details

  • Cyber42 Round 2 Initiative Selection 
  • Cyber42 Round 2 Challenge #8: Industry Breach 
  • Cyber42 Round 2 Challenge #9: Security Misconfiguration 
  • Cyber42 Round 2 Challenge #10: Miracle on DevOps Way 
  • Cyber42 Round 2 Challenge #11: Shadow AI

Full Topic Details

  • Security Engineering 
    • Overview 
  • Data Protection 
    • Cryptography Concepts 
      • Confidentiality, Integrity, Authentication, Non-Repudiation 
    • Encryption Algorithms 
      • Symmetric, Asymmetric, Key Exchange, Hashing, Digital Signature 
    • Encryption Applications 
      • TLS, PKI, Blockchain, Quantum 
  • Application Security 
    • Secure SDLC 
    • Application Attacks 
      • OWASP Top Ten 
    • Application Security Tools 
      • SAST, SCA, DAST, WAF, RASP 
  • DevSecOps 
    • DevOps Toolchain and Pipeline 
    • Continuous Integrations and Continuous Delivery (CI / CD)
    • Infrastructure as Code (IaC) 
    • Container Security 
  • GenAI and LLM Security 
    • Innovations in Artificial Intelligence 
      • Transformer Architecture 
    • LLM Application Architecture 
      • AWS Generative AI Security Scoping Matrix 
      • AWS Agentic AI Security Scoping Matrix
    • LLM Attacks 
      • OWASP Top Ten for LLM Applications
      • OWASP Top Ten for Agentic Applications
      • MITRE ATLAS 
      • Overreliance, Prompt Injection, Sensitive Information Disclosure, Model Theft, Training Data Poisoning, Excessive Agency, Jailbreaking 
    • GenAI Security Controls 
      • NIST AI Risk Management Framework (RMF) 
      • AI Security Policy 
      • LLMSecOps and Defensive Concepts
      • AI Security Tools and Mitigations 

Section 4Security Management and Leadership

This section equips managers to lead security initiatives, covering vulnerability management, security awareness, privacy concepts, vendor negotiation, and effective project execution to foster a security-aware culture and drive project success.

Topics covered

  • Vulnerability Management
  • Security Awareness
  • Privacy and Negotiation Primers
  • Vendor Analysis
  • Managing and Leading Teams

Labs

  • Cyber42 Round 3 Initiative Selection 
  • Patching Problems
  • Let It Be Known!
  • Tough Negotiations
  • Managing Resistance

Overview 

Section Four covers what managers need to know about leading security initiatives. Every security leader should know how to build a vulnerability management program and the associated process to successfully find and fix vulnerabilities. Additionally, security awareness is a huge component of any security program that helps drive activities to change human behavior and create a more risk-aware and security-aware culture. Since data protection is a major global issue, we discuss the distinction between privacy and security to give managers a primer on key privacy requirements and concepts. To implement new initiatives, security leaders must also develop negotiation skills and conduct thorough analysist of vendors. Finally, for any project or initiative, security leaders must also be able to drive effective project execution. Having a well-grounded understanding of the management and leadership practices makes it easier to move your projects forward. 

Full Lab Details 

  • Cyber42 Round 3 Initiative Selection 
  • Cyber42 Round 3 Challenge #12: Patching Problems 
  • Cyber42 Round 3 Challenge #13: Let It Be Known! 
  • Cyber42 Round 3 Challenge #14: Tough Negotiations 
  • Cyber42 Round 3 Challenge #15: Managing Resistance 

Full Topic Details

  • Vulnerability Management 
    • PIACT Process 
    • Prioritizing Vulnerabilities 
      • Common Vulnerability Scoring System (CVSS) 
      • Exploit Prediction Scoring System (EPSS)
      • Known Exploited Vulnerabilities (KEV)
    • Finding and Fixing Vulnerabilities 
    • Communicating and Managing Vulnerabilities 
  • Security Awareness 
    • Maturity Model 
    • Human Risks 
  • Privacy Primer 
    • Privacy and Security 
    • Requirements and Regulations 
    • Privacy Engineering 
  • Negotiations Primer 
    • Negotiations Strategies 
  • Vendor Analysis 
    • Product Analysis and Selection 
    • Analytical Hierarchy Process (AHP) 
  • Managing and Leading Teams 
    • Managing Projects 
    • Leading Teams 
    • Going From Good to Great 

Section 5Detecting and Responding to Attacks

Section five focuses on detection and response, covering SIEM and SOC functions, incident response, business continuity, disaster recovery, and physical security controls for comprehensive security operations management.

Topics covered

  • Logging and Monitoring
  • Security Operations Center (SOC)
  • Cyber Incident Management
  • Contingency Planning
  • Physical Security

Labs

  • Cyber42 Round 4 Initiative Selection
  • The High Price of Visibility and Cost Cutting
  • Ransomware Response
  • New Guy in Town
  • Opportunity Knocks

Overview

Section Five focuses on detection and response capabilities. This includes gaining appropriate visibility via logging, monitoring, and strategic thinking about a security information and event management (SIEM) system. Once implemented, the logs in a SIEM are a core component of any Security Operations Center (SOC). We'll discuss the key functions of a SOC along with how to manage and organize your organization's security operations. The incident response process is discussed in relation to identifying, containing, eradicating, and recovering from security incidents. This leads into a discussion of longer-term business continuity planning and disaster recovery. Managers must also understand physical security controls that, when not implemented appropriately, can cause technical security controls to fail or be bypassed.

Full Lab Details

  • Cyber42 Round 4 Initiative Selection
  • Cyber42 Round 4 Challenge #16: The High Price of Visibility
  • Cyber42 Round 4 Challenge #17: Cost Cutting
  • Cyber42 Round 4 Challenge #18: Ransomware Response
  • Cyber42 Round 4 Challenge #19: New Guy in Town
  • Cyber42 Round 4 Challenge #20: Opportunity Knocks

Full Topic Details

  • Logging and Monitoring
    • SIEM Deployment Best Practices
    • Evolution of Detection Capabilities
  • Security Operations Center (SOC)
    • SOC Functional Components 
    • Models and Structure 
    • Tiered vs. Tierless SOCs 
    • Managing and Organizing a SOC 
  • Cyber Incident Management
    • PICERL Process 
    • NIST Incident Handling Lifecycle 
  • Contingency Planning 
    • Business Continuity Planning (BCP) 
    • Disaster Recovery (DR) 
  • Physical Security 
    • Issues and Controls 

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A laptop or mobile device with the latest web browser is required to play the Cyber42 leadership simulation game.

The Cyber42 game used in this course is hosted on the ranges.io platform. Students must have a computer that does not restrict access to ranges.io. Corporate machines may have a VPN, intercepting proxy, or egress firewall filter that causes connection issues communicating with third-party websites. Students must be able to configure or disable these services to be able to access the Cyber42 game.

If you have additional questions about the laptop specifications, please contact customer service.

LDR512 training is recommended for a diverse range of individuals, including:

  • Information security officers
  • Security directors
  • Security managers
  • Aspiring security leaders
  • Aspiring CISOs
  • Security personnel who have team lead or management responsibilities

The GIAC Security Leadership (GSLC) certification validates a practitioner's understanding of governance and technical controls focused on protecting, detecting, and responding to security issues. GSLC certification holders have demonstrated knowledge of data, network, host, application, and user controls along with key management topics that address the overall security lifecycle.

  • Building a security program that meets business needs
  • Managing security operations and teams
  • Managing security projects and the lifecycle of the program

More Certification Details

  • Electronic courseware containing the entire course content
  • Printed course books
  • Access to the Cyber42 security leadership simulation game
  • MP3 audio files of the complete course lecture

This course is designed for practitioners taking on greater security management responsibilities. It covers the core areas of security leadership and assumes a basic understanding of technology, networks, and security. For those who are new to the field and have no background knowledge, the recommended starting point is the SEC301: Introduction to Information Security course. While SEC301 is not a prerequisite, it will provide the introductory knowledge to maximize the experience with LDR512.

LDR512 is a part of the SANS Cybersecurity Leadership Curriculum and is one of three courses that make up the Transformational Cybersecurity Leaders Triad, alongside LDR514 and LDR521. The transformational triad forms a comprehensive leadership development program designed to develop well-rounded security leaders capable of building, leading, and maturing effective cybersecurity initiatives.

It is also a part of the SANS Cyber Risk Officer Triad, which includes LDR519 and LDR553. This comprehensive path develops well-rounded modern security leaders who are equipped to build programs to manage information risks and lead teams in times of intense pressure.

What Comes Next?

Security management is all about managing information risk. This means that you need the appropriate level of technical knowledge and leadership skills to gain the respect of technical team members, understand what technical staff are actually doing, and appropriately plan and manage security projects and initiatives. This is a big and important job that requires an understanding of a wide array of security topics. Being an effective security leader requires you to get up to speed quickly on information security issues and terminology to build a modern security program. Creating a high performing security team means that you can anticipate what security capabilities need to be built to enable the business and mitigate threats.

The LDR512: Security Leadership Essentials for Managers course can propel your career by:

  • Building Leadership Confidence: Gain decision-making skills tailored for security environments.
  • Providing Key Cybersecurity Insights: Understand essential security concepts, even without a technical background.
  • Enhancing Incident Management: Learn to respond to security challenges effectively.
  • Improving Communication Skills: Bridge the gap between technical teams and executive leadership.
  • Strengthening Your Career Trajectory: Increase your qualifications for security leadership roles with a SANS credential.
  • Connecting You with the SANS Network: Access a valuable community of cybersecurity professionals for ongoing support.

This course equips you with foundational skills and credibility to advance in cybersecurity leadership roles.

Relevant Job Roles

Cyber Risk Officer

Cybersecurity Leadership

Lead cybersecurity risk strategy at the highest level.

Explore learning path

Strategic Planning (ITSP)

Skills Framework for the Information Age

Development of long-term technology roadmaps that support enterprise goals and capability development. Focus includes alignment of IT investments with business outcomes.

Explore learning path

Privacy Compliance Manager (DCWF 732)

DoD 8140: Cyber Enablers

Leads privacy program development and compliance oversight to ensure adherence to privacy laws, standards, and executive data protection needs.

Explore learning path

IT Investment/Portfolio Manager (DCWF 804)

DoD 8140: Cyber Enablers

Oversees a portfolio of IT capabilities aligned to enterprise goals, prioritizing needs, solutions, and value delivery to the organization.

Explore learning path

Secure Project Management (OPM 802)

NICE: Oversight and Governance

Responsible for overseeing and directly managing technology projects. Ensures cybersecurity is built into projects to protect the organization’s critical infrastructure and assets, reduce risk, and meet organizational goals. Tracks and communicates project status and demonstrates project value to the organization.

Explore learning path

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Systems Security Management (OPM 722)

NICE: Oversight and Governance

Responsible for managing the cybersecurity of a program, organization, system, or enclave.

Explore learning path

Communications Security (COMSEC) Management (OPM 723)

NICE: Oversight and Governance

Responsible for managing the Communications Security (COMSEC) resources of an organization.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 27

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources